
I’m using a Nexus 5020, and attempting to trunk a 7606 running service provider code…but for some reason VLANs aren’t passing.
I issue the following on the 7606:
7606#show int te1/1 trunk
Port Mode Encapsulation Status Native vlan
Te1/1 on 802.1q trunking 1
Port Vlans allowed on trunk
Te1/1 1650-1699
Port Vlans allowed and active in management domain
Te1/1 1650-1653
Port Vlans in spanning tree forwarding state and not pruned
Te1/1 1650-1653
This tells me everything is passing here…what happens when I do the same on the Nexus side:
Nexus5020# show int e1/17 trunk
--------------------------------------------------------------------------------
Port Native Status Port
Vlan Channel
--------------------------------------------------------------------------------
Eth1/17 1 trunking --
--------------------------------------------------------------------------------
Port Vlans Allowed on Trunk
--------------------------------------------------------------------------------
Eth1/17 1,1650-1699
--------------------------------------------------------------------------------
Port Vlans Err-disabled on Trunk
--------------------------------------------------------------------------------
Eth1/17 none
--------------------------------------------------------------------------------
Port STP Forwarding
--------------------------------------------------------------------------------
--------------------------------------------------------------------------------
Port Vlans in spanning tree forwarding state and not pruned
--------------------------------------------------------------------------------
--------------------------------------------------------------------------------
Port Vlans Forwarding on FabricPath
--------------------------------------------------------------------------------
Eth1/17 none
As you can see above, none of the VLANs are “STP Forwarding”…but what could be the problem?
It turns out that Nexus chassis have a new feature called Bridge Assurance. It is an enhancement that helps protect against unidirectional link failure. Any port designated as “spanning-tree port type network” has it enabled by default. It expects that the switch on the other end supports the feature and is sending crafted BPDUs over to you. If you happen to be trunking to a standard catalyst switch, then it basically blocks all VLANs from passing on the port! How do we work around it…by disabling it.
You have to globally disable the feature with:
no spanning-tree bridge assurance
.
Magically, your VLANs will begin passing:
Nexus5020# show int e1/17 trunk
--------------------------------------------------------------------------------
Port Native Status Port
Vlan Channel
--------------------------------------------------------------------------------
Eth1/17 1 trunking --
--------------------------------------------------------------------------------
Port Vlans Allowed on Trunk
--------------------------------------------------------------------------------
Eth1/17 1,1650-1699
--------------------------------------------------------------------------------
Port Vlans Err-disabled on Trunk
--------------------------------------------------------------------------------
Eth1/17 none
--------------------------------------------------------------------------------
Port STP Forwarding
--------------------------------------------------------------------------------
Eth1/17 1,1650-1653
--------------------------------------------------------------------------------
Port Vlans in spanning tree forwarding state and not pruned
--------------------------------------------------------------------------------
--------------------------------------------------------------------------------
Port Vlans Forwarding on FabricPath
--------------------------------------------------------------------------------
Eth1/17 none
This seems to be a little documented feature and generally takes a little google-fu to find it. Good luck and happy switching my friends.
Leave a Reply